Key takeaways
- Unapproved or unvetted AI tools can create real risks.
- Don’t enter identifiable student or sensitive University information into an AI tool unless the tool and its intended use have been approved.
- Before using a new AI tool or AI app builder with University data, check with Information Technology Services (ITS) to make sure it’s appropriate and secure.
If you’ve ever pasted a syllabus into ChatGPT or Claude for feedback, uploaded a spreadsheet to an AI tool to identify trends, or used a free AI note taker during a student advising meeting, you may have encountered “shadow AI.”
That doesn’t mean employees should be afraid to use AI. But when University or student data is involved, a quick check before clicking “submit” can keep sensitive information from ending up somewhere it shouldn’t.
What is shadow AI?
Shadow AI refers to artificial intelligence tools or systems used for work without an organization’s IT or security team reviewing or monitoring them.
When ITS reviews a tool, staff members consider questions most users shouldn’t have to answer themselves: Where does the information go? Who can access it? How long is it retained? Could it be used to train an AI model?
With an unapproved tool, those protections might not be in place.
The biggest concern: Student data
For universities, one of the most significant risks of using AI is potential exposure of information protected by the Family Educational Rights and Privacy Act (FERPA), including grades, financial aid status, disciplinary records, disability accommodations and advising notes.
Entering any identifiable student information, including that covered by FERPA, into an unvetted AI platform could mean losing control of how that information is stored, processed or shared.
Beyond student data exposure, shadow AI creates several other concerns for universities:
- Regulatory and compliance exposure. Beyond FERPA, tools handling health information, research data or financial aid records can implicate HIPAA, grant-funding requirements or state privacy laws. Shadow AI tools can bypass the data-handling requirements defined by these laws, opening the door to fines, investigations and lawsuits.
- No audit trail. If an AI-generated recommendation, grade calculation or admissions summary is later questioned, outputs from shadow AI are usually not traceable. If something goes wrong, there’s no way to verify what data was used or how it was processed.
- Research and IP concerns. Faculty using AI tools to help draft grant proposals or analyze unpublished research data risk exposing prepublication findings or proprietary methods to third-party servers with unknown retention policies.
- Institutional reputational risk. Public data exposure tied to student records, even an accidental one from a well-intentioned staff project, can damage trust with students, families and accreditors.
Three habits for safer AI use
1. Check before you paste.
Before entering names, grades, health information, financial aid details or other identifiable student information into an AI tool, confirm that the tool and its intended use have been approved.
2. Be cautious with AI app builders.
“No-code” and “vibe-coding” platforms can quickly create forms, portals and other tools, but their data storage and visibility settings may create risks. Involve ITS before using one with University data.
3. When in doubt, ask.
A quick question before using a new tool is much easier to address than potential data exposure afterward.
AI can be a valuable tool for saving time, generating ideas and improving workflows. Using it responsibly starts with knowing what information you’re sharing and whether the tool is an appropriate place to share it.